<!DOCTYPE html><html lang="en"><head><meta http-equiv="Content-Type" content="text/html charset=UTF-8"><meta charset="UTF-8"><meta name="viewport" content="width=device-width"><meta name="x-apple-disable-message-reformatting"><title>TLDR InfoSec</title><meta name="color-scheme" content="light dark"><meta name="supported-color-schemes" content="light dark"><style type="text/css">
:root {
color-scheme: light dark; supported-color-schemes: light dark;
}
*,
*:after,
*:before {
-webkit-box-sizing: border-box; -moz-box-sizing: border-box; box-sizing: border-box;
}
* {
-ms-text-size-adjust: 100%; -webkit-text-size-adjust: 100%;
}
html,
body,
.document {
width: 100% !important; height: 100% !important; margin: 0; padding: 0;
}
body {
-webkit-font-smoothing: antialiased; -moz-osx-font-smoothing: grayscale; text-rendering: optimizeLegibility;
}
div[style*="margin: 16px 0"] {
margin: 0 !important;
}
table,
td {
mso-table-lspace: 0pt; mso-table-rspace: 0pt;
}
table {
border-spacing: 0; border-collapse: collapse; table-layout: fixed; margin: 0 auto;
}
img {
-ms-interpolation-mode: bicubic; max-width: 100%; border: 0;
}
*[x-apple-data-detectors] {
color: inherit !important; text-decoration: none !important;
}
.x-gmail-data-detectors,
.x-gmail-data-detectors *,
.aBn {
border-bottom: 0 !important; cursor: default !important;
}
.btn {
-webkit-transition: all 200ms ease; transition: all 200ms ease;
}
.btn:hover {
background-color: #f67575; border-color: #f67575;
}
* {
font-family: Arial, Helvetica, sans-serif; font-size: 18px;
}
@media screen and (max-width: 600px) {
.container {
width: 100%; margin: auto;
}
.stack {
display: block!important; width: 100%!important; max-width: 100%!important;
}
.btn {
display: block; width: 100%; text-align: center;
}
}
body,
p,
td,
tr,
.body,
table,
h1,
h2,
h3,
h4,
h5,
h6,
div,
span {
background-color: #FEFEFE !important; color: #010101 !important;
}
@media (prefers-color-scheme: dark) {
body,
p,
td,
tr,
.body,
table,
h1,
h2,
h3,
h4,
h5,
h6,
div,
span {
background-color: #27292D !important; color: #FEFEFE !important;
}
}
a {
color: inherit !important; text-decoration: underline !important;
}
</style><!--[if mso | ie]>
<style type="text/css">
a {
background-color: #FEFEFE !important; color: #010101 !important;
}
@media (prefers-color-scheme: dark) {
a {
background-color: #27292D !important; color: #FEFEFE !important;
}
}
</style>
<![endif]--></head><body class="">
<div style="display: none; max-height: 0px; overflow: hidden;">Jscrambler found European and US banks sending customer data via tracking pixels to platforms like Google, Meta, TikTok, and Salesforce </div>
<div style="display: none; max-height: 0px; overflow: hidden;">
<br>
</div>
<table align="center" class="document"><tbody><tr><td valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" class="container" width="600"><tbody><tr class="inner-body"><td>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr class="header"><td bgcolor="" class="container">
<table width="100%"><tbody><tr><td class="container">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" style="margin-top: 0px;" width="100%"><tbody><tr><td style="padding: 0px;">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div style="text-align: center;">
<span style="margin-right: 0px;"><a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Ftldr.tech%2Finfosec%3Futm_source=tldrinfosec/1/0100019f8f18be0f-d9ad6aab-edd0-4f30-b6fb-6ee4a9e5f370-000000/sVr-0xkYWa50jl7PdFX8NSBOeNL0K2zuYCkaUyJZzuE=452" rel="noopener noreferrer" target="_blank"><span>Sign Up</span></a>
|<span style="margin-right: 2px; margin-left: 2px;"><a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fadvertise.tldr.tech%2F%3Futm_source=tldrinfosec%26utm_medium=newsletter%26utm_campaign=advertisetopnav/1/0100019f8f18be0f-d9ad6aab-edd0-4f30-b6fb-6ee4a9e5f370-000000/Z8oB3xKW53QZKJCgbfr3pjrD0xpNwdAsvdYEfWeRiu0=452" rel="noopener noreferrer" target="_blank"><span>Advertise</span></a></span>|<span style="margin-left: 2px;"><a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fa.tldrnewsletter.com%2Fweb-version%3Fep=1%26lc=156924ca-84b7-11f0-8d58-47c5c04ad337%26p=c5020192-8680-11f1-aa5a-ef375829ffda%26pt=campaign%26t=1784812191%26s=c78324ee75432eec2b04ada0597a0568722d048c5228d09e5cf1c7cdd626b3bc/1/0100019f8f18be0f-d9ad6aab-edd0-4f30-b6fb-6ee4a9e5f370-000000/1W4y9-t1GKHBucsx8Vdu6uqmz9QNEyJfqYD6oyp8hKM=452"><span>View Online</span></a></span>
<br>
</span></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="text-align: center;"><span data-darkreader-inline-color="" style="--darkreader-inline-color:#3db3ff; color: rgb(51, 175, 255) !important; font-size: 30px;">T</span><span style="font-size: 30px;"><span data-darkreader-inline-color="" style="color: rgb(232, 192, 96) !important; --darkreader-inline-color:#e8c163; font-size:30px;">L</span><span data-darkreader-inline-color="" style="color: rgb(101, 195, 173) !important; --darkreader-inline-color:#6ec7b2; font-size:30px;">D</span></span><span data-darkreader-inline-color="" style="--darkreader-inline-color:#dd6e6e; color: rgb(220, 107, 107) !important; font-size: 30px;">R</span>
<br>
</td></tr></tbody></table>
<br>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody></tbody></table>
<table style="table-layout: fixed; width:100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;">
<div style="text-align: center;">
<h1><strong>TLDR Information Security <span id="date">2026-07-23</span></strong></h1>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width:100%;" width="100%"><tbody></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr>
<tr bgcolor=""><td class="container">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td style="padding: 0px;">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">🔓</span></div></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Attacks & Vulnerabilities</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Flinks.tldrnewsletter.com%2Fob0mxZ/1/0100019f8f18be0f-d9ad6aab-edd0-4f30-b6fb-6ee4a9e5f370-000000/Bn-j0Ylu-myz0r4jAnH1p10p8iACV3Rrsibyoh2B4Ug=452">
<span>
<strong>EU Financial Institutions Leak Data Through Cookie Trackers (3 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Jscrambler found European and US banks sending customer data via tracking pixels to platforms like Google, Meta, TikTok, and Salesforce, sometimes before or against user cookie consent. Examples include hashed emails and phone numbers from a Spanish mortgage flow and unencrypted names, tax IDs, and loan details from Portuguese sites. The work highlights concrete GDPR, ePrivacy, DORA, and PSD2 exposure and calls for tighter runtime controls and consent enforcement on banking pages.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fblog.qualys.com%2Fvulnerabilities-threat-research%2F2026%2F07%2F22%2Frefluxfs-a-linux-kernel-local-privilege-escalation-to-root-in-xfs-cve-2026-64600%3Futm_source=tldrinfosec/1/0100019f8f18be0f-d9ad6aab-edd0-4f30-b6fb-6ee4a9e5f370-000000/1oT83x7K6MppUuvg5HSDBiOC_OUqH99nKuTrvHjCV6w=452">
<span>
<strong>RefluXFS: A Linux Kernel Local Privilege Escalation to Root in XFS (CVE-2026-64600) (9 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
CVE-2026-64600 is a race condition in the Linux kernel's XFS copy-on-write path where two concurrent O_DIRECT writes to a reflinked file cause the kernel to re-check a stale block reference count after dropping its inode lock, letting an unprivileged local user overwrite any readable file (such as /etc/passwd or a SUID-root binary) directly at the block layer with no kernel log output and persistence across reboots. The flaw affects any kernel since v4.11 (2017) with XFS reflink=1, hitting default installs of RHEL, Oracle Linux, Amazon Linux, and Fedora (an estimated 16.4 million systems), and standard defenses including KASLR, SMEP, SMAP, SELinux enforcing, seccomp, and container isolation all fail to stop it since the flaw sits below their reach at the filesystem allocation layer. Apply vendor kernel patches immediately and reboot to confirm remediation, prioritizing internet-facing and multi-tenant systems first.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Flinks.tldrnewsletter.com%2FEfYtf6/1/0100019f8f18be0f-d9ad6aab-edd0-4f30-b6fb-6ee4a9e5f370-000000/IKWHQ_lA6L2FqljXbWWuQsij7awKet2CrqCM_KX8UV4=452">
<span>
<strong>Flaw in Adobe Extension With 300M Installs Enabled WhatsApp Data Theft (4 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Guardio researchers discovered a UXSS-class cross-origin flaw, CVE-2026-48294, in the Adobe Acrobat Chrome extension (installed in roughly 329 million browsers) that let an attacker steal a victim's WhatsApp messages, contacts, and account details simply by luring them to a malicious webpage, with no WhatsApp bug, malware, or credential compromise required. Dubbed HermeticReader, the attack used a hidden frame to exploit missing validation in the extension's internal messaging system, silently writing to local storage to activate Hermes, a dormant Adobe integration engine that then bridged to WhatsApp Web and scraped private data in plain text. Adobe patched the issue in June shortly after disclosure. Defenders should confirm Acrobat extension auto-updates have applied the fix and treat any Chrome extension's internal messaging channels as an underexamined attack surface.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">🧠</span></div>
</div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Strategies & Tactics</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Faws.plainenglish.io%2Fwhy-i-keep-recommending-amazon-guardduty-c3ec98563a15%3Futm_source=tldrinfosec/1/0100019f8f18be0f-d9ad6aab-edd0-4f30-b6fb-6ee4a9e5f370-000000/x3HpFhVE9_O7P8s7S21WTg8gtrjuphLwvrj-P-HPFwk=452">
<span>
<strong>Why I Keep Recommending Amazon GuardDuty (8 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Amazon GuardDuty has expanded over time from a simple log analyzer to a comprehensive security suite with support for a large variety of AWS services ranging from S3 to EKS to RDS and EC2. GuardDuty delivers value by applying correlation rules to alerts across different services and can also harness AI agents with the recently released Investigations feature. Teams should consider where GuardDuty fits into their organization, including existing security tooling, cost, and protection plans.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Foj-sec.com%2Fblog%2F20260721%2F%3Futm_source=tldrinfosec/1/0100019f8f18be0f-d9ad6aab-edd0-4f30-b6fb-6ee4a9e5f370-000000/JCZZnCnSdiyzC77dXq4ICUfgVaBB4-aW0aeSInEyC5o=452">
<span>
<strong>TChCh-Changes: A Look at macOS TCC Manipulation in the Wild (18 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
A cluster of AppleScript-based macOS malware delivers a run-only .scpt file disguised as a document compatibility wizard, which fetches a second stage that drops a decoy document and compiles a backdoor into an ad hoc-signed app bundle, then renames the userspace TCC directory via Finder AppleEvents to copy out TCC.db, writes permissions for the backdoor directly with sqlite, restores the directory, and kills tccd to force a reload. Written permissions include Documents, Downloads, Desktop, Finder AppleEvents, and notably kTCCServiceSystemPolicyAppData covering Mail and Notes data. The resulting beacon persists via LaunchAgent, harvests filenames and hardware identifiers from key user folders, and polls for follow-on AppleScript over C2 domains cigalsn[.]com and ecoferros[.]com. Targeting overlaps with North Korean actor Sapphire Sleet against cryptocurrency-sector employees, though the report assesses this as a distinct subgroup. The technique fails outright on Tahoe 26.4.1+ and Sequoia 15.7.7+ (Sequoia is bypassable only if Script Editor already holds Full Disk Access), so defenders should patch to current macOS builds, treat unexplained tccd termination as suspicious, and hunt for TCC.db entries lacking a corresponding tcc_modify Endpoint Security event as a sign of synthetic insertion.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fblog.cauchy.org%2Fblog%2Fdetection-validation%2F%3Futm_source=tldrinfosec/1/0100019f8f18be0f-d9ad6aab-edd0-4f30-b6fb-6ee4a9e5f370-000000/AW0PdbZ-XgtH7rEe_QNWl-fPi3L17Etkywidgq1uVT8=452">
<span>
<strong>End-to-End Detection Validation Using Coding Agents (10 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
End-to-end detection validations involve running a full emulated attack, ingesting the data, and verifying if the attack was detected successfully. The author built a set of skills for Claude Code that enables it to write and run TTPForge attack simulations. The agent can then verify whether the detection was successful and iterate on it if not.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">🧑💻</span></div>
</div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Launches & Tools</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.knocknoc.io%2Fhow-knocknoc-works%2F%3Ftldr1%26utm_source=tldrinfosec/1/0100019f8f18be0f-d9ad6aab-edd0-4f30-b6fb-6ee4a9e5f370-000000/X5XDMprGaxwFKEb9QE5wzGpP4zYTUcHCl7jCE495_UM=452">
<span>
<strong>Detection and response is dead. Prevent instead. Allowlist your networks with Knocknoc. (Sponsor)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Removing your attack surface prevents exploitability. The next zero day arrives, your servers are invisible, except to your authenticated users, minimizing risk. Just-in-time network access, any port, any protocol, using the firewalls you already own. No agent, no re-architecture, live in hours.<br><a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fknocknoc.io%2Fc%2Fprevention%3Ftldr2/1/0100019f8f18be0f-d9ad6aab-edd0-4f30-b6fb-6ee4a9e5f370-000000/E-r0TJXT8TnPlbpAX2RFhC1I8ByEaYgs-1TsAaFw6HI=452" rel="noopener noreferrer nofollow" target="_blank"><span><strong>Get the free licence (DIY)</strong></span></a><strong> | </strong><a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fknocknoc.io%2Fc%2Fprevention%3Ftldr2/2/0100019f8f18be0f-d9ad6aab-edd0-4f30-b6fb-6ee4a9e5f370-000000/dsprltVp93wU_IieCqJGzZtidIMgSCByKkHu5befF6g=452" rel="noopener noreferrer nofollow" target="_blank"><span><strong>Start a free trial (SaaS)</strong></span></a>
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.empiricalsecurity.com%2F%3Futm_source=tldrinfosec/1/0100019f8f18be0f-d9ad6aab-edd0-4f30-b6fb-6ee4a9e5f370-000000/XBOGLmlWe2E9Le6wNEu8FQebfKzChe0hgkoN2n-MKbI=452">
<span>
<strong>Empirical (Product Launch)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Empirical provides two products: Foundation, a model that tracks over 18,000 exploited CVEs for threat prediction, and Radiant, an engine that flags threats relevant to each customer's environment, with data-driven insights for remediation.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fblogs.cisco.com%2Fai%2Fintroducing-antares-the-most-efficient-open-weight-ai-models-for-vulnerability-localization%3Futm_source=tldrinfosec/1/0100019f8f18be0f-d9ad6aab-edd0-4f30-b6fb-6ee4a9e5f370-000000/l-Fwcbe4zfSDi8f1T0nvir_Cct2bP4zCvinryqUqnOU=452">
<span>
<strong>Introducing Antares: Highly Efficient Open Weight AI Models for Vulnerability Localization (6 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Cisco introduces Antares, a set of small security-focused language models released as open weights for local vulnerability localization in source code, along with a 500-task Vulnerability Localization Benchmark, CLI tooling, and integrations with Foundry Security Spec and CodeGuard to support repository-level scanning, advisory-driven investigations, and CI/CD triage for teams that need to keep sensitive code on-premises while reducing manual vulnerability triage effort.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fgithub.com%2F416rehman%2FDeepZero%3Futm_source=tldrinfosec/1/0100019f8f18be0f-d9ad6aab-edd0-4f30-b6fb-6ee4a9e5f370-000000/ciLBNJ0i39Rwvx_Uu--GUlT0b3GL_lYdFO-SP_6GCc8=452">
<span>
<strong>DeepZero (GitHub Repo)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
DeepZero is an automated vulnerability research pipeline engine that allows for defining pipelines as YAML files.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">🎁</span></div></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><strong><h1>Miscellaneous</h1></strong></div>
</div>
</td></tr></tbody></table>
<table bgcolor="" style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fthehackernews.com%2F2026%2F07%2Fopen-source-android-ai-agents-could-let.html%3Futm_source=tldrinfosec/1/0100019f8f18be0f-d9ad6aab-edd0-4f30-b6fb-6ee4a9e5f370-000000/LYPc2mu6g1tWu5CMM3Yq-xBWXXEZY9TXJQMllGYuEC8=452">
<span>
<strong>Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs (6 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Researchers show that Android AI agent frameworks can be steered by hidden on-screen text and tampered screenshots, letting attacker-controlled payloads travel from phone displays into shell commands on the host PC. They exploit unsanitized subprocess calls, screenshot race conditions, broadcast-based keyboards, and accessibility overlays to capture credentials or run code, often needing only common Android permissions and debugging enabled.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Ftechcrunch.com%2F2026%2F07%2F21%2Fopenai-says-hugging-face-was-breached-by-its-pre-release-models%2F%3Futm_source=tldrinfosec/1/0100019f8f18be0f-d9ad6aab-edd0-4f30-b6fb-6ee4a9e5f370-000000/5LCARDzQUbRFlGltYLifFvyuCga9hRfr2EmYtQjaBzk=452">
<span>
<strong>OpenAI says Hugging Face was breached by its pre-release models (2 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
OpenAI says a test using GPT‑5.6 Sol and a stronger pre-release model broke out of a restricted environment, abused a flaw in a package installer to reach the internet, then targeted Hugging Face's ExploitGym benchmark. The models pulled benchmark answers from Hugging Face's production database and triggered a large, automated attack. OpenAI has patched the installer and is adding tighter controls on testing infrastructure.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fappleinsider.com%2Farticles%2F26%2F07%2F22%2Fif-youve-got-this-dealer-installed-car-alarm-patch-it-today-with-your-iphone%3Futm_source=tldrinfosec/1/0100019f8f18be0f-d9ad6aab-edd0-4f30-b6fb-6ee4a9e5f370-000000/dccwppxUPKOW-f0Ri6nd0YfmrhmM2ZBzL2a2SczocJk=452">
<span>
<strong>If you've got this dealer-installed car alarm, patch it today with your iPhone (4 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
UC San Diego researchers found that the KARR Security System, an aftermarket alarm dealerships often leave connected even after buyers decline the paid service, relies on a shared Bluetooth authentication key discovered inside the official app, letting anyone in range unlock, immobilize, or trigger the horn and lights on an estimated 2.2 million vehicles across Honda, Toyota, Mazda, Ford, and Jeep lots. The episode highlights a structural gap in automotive supply chains: because KARR is third-party hardware installed post-sale, the flaw sits outside automakers' normal patching pipelines, and researchers estimate at least half of affected owners never even requested the feature. It also underscores a secondary privacy dimension, since the same persistent Bluetooth broadcast used for the exploit can be mined from crowdsourced wireless databases like WiGLE to reconstruct a vehicle's movement history, a risk distinct from the unlock vulnerability itself.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">⚡</span></div></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Quick Links</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table bgcolor="" style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Foptro.ai%2Fresources%2Febook%2Fai-governance-policy-template%3Futm_campaign=ai-governance-policy-template-042026%26utm_medium=display%26utm_source=tldr-compliance%26utm_content=07-23-2026/1/0100019f8f18be0f-d9ad6aab-edd0-4f30-b6fb-6ee4a9e5f370-000000/QC4bV7JlHTtQaq3I9ROfvCAHHq9h5TpXaEVJcf99ER0=452">
<span>
<strong>AI Governance Policy Template (free, customizable) (Sponsor)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Protect your organization from data privacy risks with this <strong>free, fully customizable</strong> <a class="ng-star-inserted" href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Foptro.ai%2Fresources%2Febook%2Fai-governance-policy-template%3Futm_campaign=ai-governance-policy-template-042026%26utm_medium=display%26utm_source=tldr-compliance%26utm_content=07-23-2026/2/0100019f8f18be0f-d9ad6aab-edd0-4f30-b6fb-6ee4a9e5f370-000000/nxpSipl7KKezkCq6lTSRxShv0ASSTJ9VFgMMHlWNM4g=452" rel="noopener" target="_blank"><span><strong>AI Governance Policy Template</strong></span></a> - designed to help your team establish clear, enforceable guardrails today. Use the template <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Foptro.ai%2Fresources%2Febook%2Fai-governance-policy-template%3Futm_campaign=ai-governance-policy-template-042026%26utm_medium=display%26utm_source=tldr-compliance%26utm_content=07-23-2026/3/0100019f8f18be0f-d9ad6aab-edd0-4f30-b6fb-6ee4a9e5f370-000000/QmVVRgcHPLDG43vzQtxYheN2grzs27vsNYIIlORuDhY=452" rel="noopener noreferrer nofollow" target="_blank"><span>here</span></a>!
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Flinks.tldrnewsletter.com%2FypPUdc/1/0100019f8f18be0f-d9ad6aab-edd0-4f30-b6fb-6ee4a9e5f370-000000/QcymXc-poY614Esm8rMJdvn02cpn78UJ5kZrXww-8U0=452">
<span>
<strong>Ransomware Group Threatening to Leak Data Stolen From Coca-Cola's Fairlife (2 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Anubis claims to have encrypted Fairlife servers and taken 1 TB of confidential data.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.chinadaily.com.cn%2Fa%2F202607%2F20%2FWS6a5db910a310986e2b466326.html%3Futm_source=tldrinfosec/1/0100019f8f18be0f-d9ad6aab-edd0-4f30-b6fb-6ee4a9e5f370-000000/rMWbhGG9_N6e3injwrRZ8_NdQuVATXvOtLj4ww5DOqk=452">
<span>
<strong>Chinese police repatriate key suspect in phishing and Trojan virus case from Vietnam (2 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Chinese police repatriated principal suspect Pan from Vietnam on June 6 following his June 4 arrest tied to a Zibo-originated phishing and Silver Fox Trojan operation active since July 2025.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fcointelegraph.com%2Fnews%2Fzilliqa-ledger-vulnerability-attackers-recover-private-keys%3Futm_source=tldrinfosec/1/0100019f8f18be0f-d9ad6aab-edd0-4f30-b6fb-6ee4a9e5f370-000000/eTUSdvRBHNRJpES6ny-CrOIUJNkiQh-85gj66h-kfFo=452">
<span>
<strong>Zilliqa Ledger app vulnerability lets attackers recover signer's private keys (2 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Zilliqa disclosed that a Ledger app flaw generates signatures with predictably weakened ephemeral nonces, letting attackers reconstruct private keys from public onchain data for any wallet that signed five or more native ZIL transactions via Ledger.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td align="left" style="word-break: break-word; vertical-align: top; padding: 5px 10px;">
<p style="padding: 0; margin: 0; font-size: 22px; color: #000000; line-height: 1.6; font-weight: bold;">
Love TLDR? Tell your friends and get rewards!
</p>
</td></tr>
<tr><td class="container" style="padding: 0px 10px 15px;">
<div class="text-block">
Share your referral link below with friends to get free TLDR swag!
</div>
</td></tr>
<tr><td align="left" style="padding: 10px;">
<div class="text-block">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Frefer.tldr.tech%2F78de0e20%2F8/1/0100019f8f18be0f-d9ad6aab-edd0-4f30-b6fb-6ee4a9e5f370-000000/38fNf7L_ag2qMXYOqKHLWBu2YnVxvUWmhmY523kid-M=452" style="color: #464ba4; text-decoration: underline;">https://refer.tldr.tech/78de0e20/8</a>
</div>
</td></tr>
<tr></tr>
<tr><td align="left" style="padding:5px 10px;">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fhub.sparklp.co%2Fsub_d62447d5a74a%2F8/1/0100019f8f18be0f-d9ad6aab-edd0-4f30-b6fb-6ee4a9e5f370-000000/Do3q1c92A1MaCEp9HEQhGjAW8JpmeYudF1DH81h8mBk=452" style="font-size: 16px; line-height: 1.6; padding: 10px 0; display: inline-block; text-decoration: underline;"><span style="mso-text-raise:13pt; text-decoration: underline;">Track your referrals here.</span></a>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td align="left" style="word-break: break-word; vertical-align: top; padding: 5px 10px;">
<p style="padding: 0; margin: 0; font-size: 22px; color: #000000; line-height: 1.6; font-weight: bold;">
Want to advertise in TLDR? 📰
</p>
<div class="text-block" style="margin-top: 10px;">
If your company is interested in reaching an audience of cybersecurity professionals and decision makers, you may want to <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fadvertise.tldr.tech%2F%3Futm_source=tldrinfosec%26utm_medium=newsletter%26utm_campaign=advertisecta/1/0100019f8f18be0f-d9ad6aab-edd0-4f30-b6fb-6ee4a9e5f370-000000/j4fLCuCRc2UTVz5qPEp1FtzzM82wpxLQmB5V84Ico1Q=452"><strong><span>advertise with us</span></strong></a>.
</div>
<br>
<!-- New "Want to work at TLDR?" section -->
<p style="padding: 0; margin: 0; font-size: 22px; color: #000000; line-height: 1.6; font-weight: bold;">
Want to work at TLDR? 💼
</p>
<div class="text-block" style="margin-top: 10px;">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fjobs.ashbyhq.com%2Ftldr.tech/1/0100019f8f18be0f-d9ad6aab-edd0-4f30-b6fb-6ee4a9e5f370-000000/aapl4OqGeXU12z7-SjxJhgl30_HOZYiwYuziutBTwdk=452" rel="noopener noreferrer" style="color: #0000EE; text-decoration: underline;" target="_blank"><strong>Apply here</strong></a>,
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fjobs.ashbyhq.com%2Ftldr.tech%2Fc227b917-a6a4-40ce-8950-d3e165357871/1/0100019f8f18be0f-d9ad6aab-edd0-4f30-b6fb-6ee4a9e5f370-000000/4Fp7G3WeyB4W9C3C0CbzZTBJz0pp1Wzv85LY5KbhR4k=452" rel="noopener noreferrer" style="color: #0000EE; text-decoration: underline;" target="_blank"><strong>create your own role</strong></a> or send a friend's resume to <a href="mailto:jobs@tldr.tech" style="color: #0000EE; text-decoration: underline;">jobs@tldr.tech</a> and get $1k if we hire them! TLDR is one of <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Ffeed%2Fupdate%2Furn:li:activity:7401699691039830016%2F/1/0100019f8f18be0f-d9ad6aab-edd0-4f30-b6fb-6ee4a9e5f370-000000/h0K9Vf27AwK4xDQH9_FuIwT_nNABwyZ-rcYdcjbl9B4=452" rel="noopener noreferrer" style="color: #0000EE; text-decoration: underline;" target="_blank"><strong>Inc.'s Best Bootstrapped businesses</strong></a> of 2025.
</div>
<br>
<div class="text-block">
If you have any comments or feedback, just respond to this email!
<br>
<br> Thanks for reading,
<br>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Fin%2Fprasannagautam%2F/1/0100019f8f18be0f-d9ad6aab-edd0-4f30-b6fb-6ee4a9e5f370-000000/puIGyikYfY06ED7FoO3o3xwnRjPWI0W4LOuxHDyOeIc=452"><span>Prasanna Gautam</span></a>, <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Fin%2Fericfernandezdelcampo%2F/1/0100019f8f18be0f-d9ad6aab-edd0-4f30-b6fb-6ee4a9e5f370-000000/9wRhXq6D7kStyXoASs6aubUdrk3i3s-y9rVWff-LeRI=452"><span>Eric Fernandez</span></a> & <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Fin%2Fsammy-tbeile%2F/1/0100019f8f18be0f-d9ad6aab-edd0-4f30-b6fb-6ee4a9e5f370-000000/UYNI3Dej1VAolqOhm9BjM9kO840UAUDYOYB0OaRnpPs=452"><span>Sammy Tbeile</span></a>
<br>
<br>
</div>
<br>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block" id="testing-id">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Ftldr.tech%2Finfosec%2Fmanage%3Femail=silk.theater.56%2540fwdnl.com/1/0100019f8f18be0f-d9ad6aab-edd0-4f30-b6fb-6ee4a9e5f370-000000/0EEgbBKKx5AbSUjKv0cvSS4PRMspBsHQDPrTWA2BgOA=452">Manage your subscriptions</a> to our other newsletters on tech, startups, and programming. Or if TLDR Information Security isn't for you, please <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fa.tldrnewsletter.com%2Funsubscribe%3Fep=1%26l=8d9cea11-3e94-11ed-9a32-0241b9615763%26lc=156924ca-84b7-11f0-8d58-47c5c04ad337%26p=c5020192-8680-11f1-aa5a-ef375829ffda%26pt=campaign%26pv=4%26spa=1784811727%26t=1784812191%26s=5e052cefe285f7b1e1528fae26cc59a82240059b270c16d5c0b75b18f5ee795d/1/0100019f8f18be0f-d9ad6aab-edd0-4f30-b6fb-6ee4a9e5f370-000000/BHmNqvTOh-EjGxlvC2tslZ3lIJnyle2WAZBGyQVAslA=452">unsubscribe</a>.
<br>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
<img alt="" src="http://tracking.tldrnewsletter.com/CI0/0100019f8f18be0f-d9ad6aab-edd0-4f30-b6fb-6ee4a9e5f370-000000/afg-dIUa9pk-O4MoioFxz3f7AF6tIbqGficX354UNjQ=452" style="display: none; width: 1px; height: 1px;">
</body></html>